4 ms·
Be serious. Apple closes security holes in iOS as they're discovered, just like every other OS vendor. Not closing them would be unthinkable, regardless of whet
by irons 16y ago
Be serious. Apple closes security holes in iOS as they're discovered, just like every other OS vendor. Not closing them would be unthinkable, regardless of whether some exploits are currently being put to popular use. The platform would suffer more if they didn't.
If anything, Apple deserves grief for not aggressively releasing patches to holes discovered in prior versions of the OS, after they've been obsoleted.
- daeken 16y agoIt's difficult to call much of what Apple has done "closing security holes". For instance, the original jailbreak required physical access, as it was done via recovery mode. This is no more a "security hole" than single-user mode on OS X.
- irons 16y agoAre you really arguing that highly portable mobile devices shouldn't be proof against an in-person attack by someone you know, say over the course of a shower, or having left your phone on your desk over lunch? Of course that's a security hole. (So is single-user mode.)
- daeken 16y agoThere are two important things here: 1) If someone has physical access to your computer/car/phone/whatever, you should consider it compromised already; it's all just a matter of how easy it is for the first person to do it. (Smart cow problem) 2) Real-world security, at the end of the day, is a tradeoff between safety and user friendliness. This is why it doesn't make sense for Hacker News to use two-factor authentication, but it does make sense for your bank. Every additional security feature has its tradeoffs; adding new ones lightly is as bad an idea as not considering security at all.
- irons 16y agoA minute ago you were saying that a vulnerability requiring physical access wasn't a security hole. Now you're saying I should consider my phone compromised because other people have physical access to it. I don't see how you can hold both positions.
- daeken 16y agoEverything from leaving JTAG interfaces active (which many devices do) to enabling you to reflash a phone without authentication (which the iPhone does) could be considered vulnerabilities. We deal with these because they make more sense than the alternative.